NexShield is a malicious Chromium browser extension that impersonates the legitimate uBlock Origin Lite ad blocker. It was distributed through malvertising that directed victims to an official browser-extension marketplace listing and was used in KongTuke, also known as Woodgnat, attack chains. The extension is largely cloned from the legitimate product and uses forged developer attribution to appear trustworthy.
NexShield delays activation, records installation lifecycle telemetry, and deliberately exhausts browser resources by creating large volumes of runtime connections. This causes browser instability or crashes and supports a ClickFix-style social-engineering variant known as CrashFix. After restart, victims are presented with a fraudulent warning and instructed to paste and execute a command through the Windows Run dialog; the extension has already placed a malicious command on the clipboard. The subsequent infection chain abuses legitimate Windows utilities and PowerShell to retrieve and execute additional payloads.
The campaign employs anti-analysis controls in its deceptive interface and downstream stages, including restrictions on developer tools and checks for security-analysis tools, virtualized environments, and enterprise domain membership. Domain-joined systems were selectively targeted for delivery of ModeloRAT, a Python-based remote-access trojan. The activity indicates a financially motivated enterprise-access operation associated with the KongTuke/Woodgnat initial-access broker.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Woodgnat attack chains used a malicious Chrome extension named NexShield as part of the CrashFix ClickFix variant.
"...a malicious browser extension called NexShield that impersonates the legitimate uBlock Origin Lite ad blocker..."
15 distinct techniques documented for this family, organized by ATT&CK tactic.
“To evade detection… uses Chrome's Alarms API to delay execution by 60 minutes… then fires every 10 minutes after the initial trigger.”
ClickFix... fake error or fake CAPTCHA tests to trick users into pasting malicious scripts into the Windows Run dialog... FileFix... manually pasting and executing malicious commands... CrashFix... trick them into manually executing code... In each case the victim is ultimately tricked into running an attacker-supplied PowerShell command.
“multiple layers of Base64 encoding and XOR… C2 IP addresses built character-by-character… junk code padding… TWO layers of string encryption… AES-256-CBC… then XOR”
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious Chrome extension used in Woodgnat's CrashFix social-engineering attack chain.
A malicious Chrome extension masquerading as uBlock Origin Lite and used in Woodgnat attack chains to facilitate the CrashFix social-engineering lure.
A malicious Chrome extension masquerading as uBlock Origin Lite and used in Woodgnat attack chains to stage the CrashFix social-engineering lure.
Fake ad-blocking Chrome/Edge extension used in a malvertising campaign; intentionally crashes the browser and presents a fraudulent 'fix' flow to lead victims into executing malicious commands, ultimately delivering additional payloads (e.g., ModeloRAT).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.